Bug 2467275 - Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
Summary: Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: httpd
Version: rawhide
Hardware: Unspecified
OS: Linux
unspecified
urgent
Target Milestone: ---
Assignee: Luboš Uhliarik
QA Contact: Fedora Extras Quality Assurance
URL: https://thehackernews.com/2026/05/cri...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-06 16:14 UTC by customercare
Modified: 2026-05-08 16:15 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-05-08 16:15:35 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description customercare 2026-05-06 16:14:11 UTC
No Builds in bodhi atm!

The vulnerability, tracked as CVE-2026-23918 (CVSS score: 8.8), has been described as a case of "double free and possible RCE" in the HTTP/2 protocol handling. This issue affects Apache HTTP Server 2.4.66 and has been addressed in version 2.4.67.



Reproducible: Always

Comment 1 Joe Orton 2026-05-08 16:15:35 UTC
See bug 2465304


Note You need to log in before you can comment on or make changes to this bug.